TArCS: Trusted and Attack-Resilient Clock Source with TEE and RDMA
Published in 17th International Symposium on Advanced Parallel Processing Technologies (APPT'26), 2026
As confidential computing technologies advance, the secure and trustworthy execution of applications has garnered increasing attention. However, recent time-based attacks have severely disrupted trust and pose significant threats to the normal functioning of applications across various fields, especially the safety of real-time systems. This highlights the critical importance of a robust trusted timekeeping infrastructure. We conduct a detailed analysis of the unique challenges in trusted timekeeping systems and propose the CIAT model, which integrates the classic Confidentiality, Integrity, and Availability framework by incorporating Timeliness. Within the CIAT model, we systematically analyze various threats, including Trust Attacks, Precision Attacks, and Availability Attacks.
To address these multifaceted challenges, we introduce the Trusted and Attack-resilient Clock Source (TArCS), a novel framework that leverages TEEs and Remote Attestation (RA) to ensure the confidentiality and integrity of time sources, and employs RDMA to enhance resilience against a wide range of time attacks. We provide rigorous security proofs for TArCS against Trust Attacks and conduct comprehensive evaluations against Precision and Availability Attacks. TArCS achieves 10us-precision in short-link tests and 4ms-precision in long-link tests, while demonstrating 23ms-level bounded precision under intensive precision attacks, outperforming the attack resilience of the state-of-the-art work. Additionally, TArCS exhibits strong scalability and reliability, ensuring consistent performance under varying system loads and network conditions.
